The hardware wallet manufacturer Trezor has announced that, due to a data breach at a third-party logistics service provider, order information for thousands of customers was leaked. The company added that its own systems and hardware wallets were not compromised by the incident and warned users about potential phishing attacks.
Which Trezor users were affected by the data leak?
According to Trezor's statement, the incident affected some new customers who received orders within the 90 days prior to August 8, 2026.
The countries where the data leak affected customers include the USA, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
According to information provided by the company, data for 11,742 customers was fully disclosed, and data for 1,947 customers was partially disclosed. Thus, the number of customers affected to some degree by the incident exceeds 13,000.
The leaked information includes customers' first and last names, delivery addresses, phone numbers, and email addresses.
Trezor: "Wallets and corporate systems are secure."
Trezor stated that the data leak did not occur directly within the company's infrastructure but rather at a third-party service provider used for order deliveries.
The company also stated that the incident was limited by its policy of retaining data for only 90 days. It was also noted that all affected customers were individually notified via email.
Trezor stated that hardware wallets, corporate systems, and the confidential information providing users access to their crypto assets were not affected by the data leak.
However, obtaining information such as name, phone number, email address, and physical address can enable malicious actors to conduct more convincing and targeted phishing campaigns.
In light of this, Trezor strongly urged its users to exercise increased vigilance in the coming period regarding suspicious messages that appear to be sent on behalf of the company or other cryptocurrency services.
The company specifically reminded users not to enter wallet backup information or recovery seed phrases on any websites and not to share this information with anyone.






